This policy explains what happens to your data when you use cristianrenosto.party. It is written to be read: if anything below is unclear, write to me and I will explain it in plain terms.
Who I am
This is a personal website operated by Cristian Renosto, an individual based in Treviso, Italy. It is not a business, there is no company behind it, and there is no commercial entity or VAT number to quote. Data protection questions come to me directly at cristian.renosto07@gmail.com.
I am the data controller for everything described here. I have not appointed a Data Protection Officer (Art. 37 GDPR): the appointment is required for large-scale monitoring or for large-scale processing of special categories of data, and this site does neither. There is no other role in this setup, so writing to me reaches the person actually responsible.
Data I collect
I collect as little as possible, and only what you choose to give me:
- Messages sent through the contact form. Your name, your email address and the message text. All three are needed to reply, so there is no way to use the form without giving them: if you would rather not send a message, use the email address at the bottom of this page instead. Your IP address is not part of the message and is never passed to the mail provider. The message reaches a mailbox on this domain and is forwarded to me; you are its author, not its recipient, and your address is set as the reply address so that replying goes back to you and not to the site.
- The page your message was sent from. Your browser tells me which page you were on when you submitted the form, and I keep only the path of it, for example
/contact, never the full address, so any parameter in the address bar is dropped. It adds nothing about you beyond what your message already says. - Your IP address, briefly, to slow down spam. To stop automated submissions, the server counts how many messages arrive from the same IP address and refuses more than five per hour. This count is held in the server's memory only, is never written to disk or to any database, and disappears when the server restarts — so it does not survive for longer than about an hour, and in practice less.
- Server logs. My host keeps short-lived technical logs (IP address, timestamp, requested URL) to detect abuse and keep the site running. They contain no message content.
- No profiling, ever. I do not build a profile of you, and nothing here is used to target advertising. See Accounts for what an account does store.
Accounts
This site has an account system, limited to addresses on @cristianrenosto.party. Creating one stores exactly three things:
- The address you sign in with, which is also the key that identifies you across my services.
- One real email address, used to send the verification link and to reach you if a password is forgotten. It is not used for anything else.
- A hashed password. Never the password itself — it is transformed with bcrypt before being stored, so a copy of the database does not contain your password.
I do not ask for a name, a surname, a phone number or a date of birth, and I do not ask you to upload a picture. The columns exist in the database and stay empty on purpose: collecting something for a possible future is not the same as collecting it because it is needed.
To verify that the second address is really yours, I email a link containing a 20-character random key. Your browser sends only the hash of that key, so a copy of the database cannot be used to verify an account or to sign in to one. The key expires after 24 hours and works once.
Signing in sets one cookie, cr_session, described below. Closing your account is a matter of writing to me at assistenza@cristianrenosto.party: I delete the row, and every service linked to you deletes its own tables through the same request. You can check what is stored about you, in its real values, on your account page.
Cookies
This site does not use advertising cookies, tracking pixels, or third-party profiling cookies of any kind. Exactly two cookies can be set, and both by us:
cr_consentrecords that you made a choice about analytics, so the banner does not ask again. It expires after 180 days and contains no identifier — only the wordallornecessary. It is set by us, not by anyone else, and is therefore exempt from consent under GDPR.cr_sessionkeeps you signed in. It is only created when you sign in, never for a visitor who has not signed in. It expires after 7 days of not using it, is markedHttpOnlyso that no script can read it, is sent only over HTTPS, and is not attached to requests coming from other sites. It carries a random token and nothing else — your address is not in it. In the database I keep only its hash, together with the IP address and the browser you signed in from, and the session can be closed at any time by signing out.
Clearing your browser storage, or using the Cookie settings link in the footer, removes it. Declining analytics leaves the site fully working.
Analytics
If — and only if — you accept, this site loads Plausible Analytics. Plausible is chosen precisely because it does not set cookies, does not fingerprint your device, and does not build a profile of you.
To be precise rather than reassuring: a request that reaches Plausible does carry personal data — your IP address among it — because that is the only way to count a visit. What Plausible does not do is keep it. The IP address is used to derive the country, then discarded; what remains is a country code and a browser family, attached to no individual. The figures I look at are the page path, the referrer, the country and the browser family. If you decline, no analytics script is downloaded at all and no request is made to any third party.
Why I am allowed to process it
- Consent (Art. 6(1)(a) GDPR) for analytics. You can withdraw it at any time from Cookie settings in the footer, and withdrawal is as easy as granting it.
- Legitimate interest (Art. 6(1)(f) GDPR) for replying to the message you wrote and for keeping the site secure. Your interest in being answered outweighs the minimal impact of holding a short message.
- Legal obligation (Art. 6(1)(c) GDPR) where applicable to the hosting provider's own logs.
- Contract (Art. 6(1)(b) GDPR) for the account: an account exists so you can use a service, and it cannot exist without an address and a password. The verification email is the one piece I process to be able to prove that the address is yours — it is not marketing, it is the check that makes the account usable.
How long your data is kept
- Contact form messages: up to 12 months from the day you write. That is the maximum, not a target: I delete a message once the conversation is over, and certainly not later than that. I do not keep a mailing list, and nothing is added to any newsletter.
- The spam counter tied to your IP: in memory only, for as long as the current hour lasts, then gone. Never on disk.
- Aggregate analytics: cannot be linked back to you, so there is nothing to delete. Plausible keeps the aggregated event itself for 24 months, their default setting.
- Server logs: a matter of days, set by the host and not by me.
- Your account: until you ask me to close it. There is no automatic expiry, because an account you still use would be deleted by a timer and a password reset you never requested is worse than a password that stays valid.
- Verification keys: the hash of each key lives for 30 days after it has been used, then it is deleted. It is a hash, not a link, so it cannot be used to sign in. Expired unused keys are swept the same way.
- Sessions: one row per sign-in, holding your address, the hash of the session token, the IP and the browser. The row is deleted 30 days after the session stops being used. Signing out closes it immediately: the cookie disappears from this device and the session stops working everywhere, including on a device you no longer have.
Who else is involved
The site is hosted on Vercel. Messages are delivered through Resend, which processes the content of your message as a mail provider. They arrive at Cloudflare, which runs the mail forwarding that moves everything sent to assistenza@cristianrenosto.party into my own mailbox — so the text of your message crosses Cloudflare's mail servers too, and the DNS of this domain is served by them. Analytics run on Plausible, but only with your consent. Each of them processes data in its own right and is bound by its own privacy terms; none of them receives an advertising profile of you. All of them are US companies, which is covered in the next section.
Transfers outside the EU
All of the providers above are companies established in the United States, so relying on them means your data is processed outside the European Economic Area. That is a transfer under Chapter V of the GDPR, and it needs a basis beyond my simply picking a convenient supplier.
What applies, and what I have done about it:
- Contractual clauses. Each of these providers publishes a data processing agreement that incorporates the European Commission's Standard Contractual Clauses (Decision 2021/914), and using them under those published terms is what brings the clauses into force between us. They are the safeguard Art. 46(2)(c) requires, and they travel with the data wherever it is stored. If you want to read the version that applies, ask me and I will point you to the provider's terms.
- Minimising what leaves the EU. Hosting and analytics are the only flows. Analytics do not start at all unless you accept them, so in the common case of a visitor who declines, nothing of yours is sent to any third country.
- The message you write. If you use the contact form, its text, your name and your email address pass through the US-based mail provider to reach me. I could not operate the form without this, which is why writing to me directly is just as easy.
- What survives anonymisation. The analytics figure that reaches my dashboard is a country code and a browser family with no identifier attached. There is nothing in it to single you out even if it were intercepted.
If you would rather no data of yours left the EU at all, decline analytics and use email instead of the form: in that case this site hands nothing to a third country, and the only processing is technical, done by my host to serve the page.
Your rights under the GDPR
You can ask me to show you the data I hold about you, correct it, delete it, restrict or object to its processing, and receive a portable copy of it. Because I do not use your data for automated decision-making or profiling, there is no automated decision to contest. You also have the right to lodge a complaint with your data protection authority, and doing so carries no consequence for you. The competent authority for this site, because the controller is established in Italy, is:
Garante per la protezione dei dati personali
Via Po, 12 — 00187 Roma (RM), Italy
www.garanteprivacy.it — a complaint can also be filed online from the site's Denuncia per violazione dati section.
I would rather you wrote to me first: most of the time the answer is a correction or a deletion I can make in a moment. I will reply within one month as the law requires, and in practice it takes me a day or two. You do not need to invoke a formal procedure — just write to me.
Security
In production the site is served only over HTTPS, with HSTS enabled. On my own machine, while I am developing, it runs on plain HTTP at localhost: that is the one context in which the connection is not encrypted, and it is not the context you are reading this in.
The contact form is submitted to my own server rather than directly from your browser to a third party, and the message is not written to any database or stored on disk. It exists in memory only for as long as it takes to hand it to the mail provider, then it is gone.
One consequence worth stating plainly: if mail delivery is not working, the form rejects your message and discards it rather than storing it for a retry. Your message is not lost because a copy was kept — it is lost because nothing was kept. If you see a failure notice, it was not delivered and you are welcome to send it again.
No system is perfectly secure, but nothing here is designed to collect more than it needs.
Changes to this policy
If this policy changes materially, the date at the top of the page changes with it. The version you are reading is always the one published here.
Contact
Questions, requests, or corrections: cristian.renosto07@gmail.com. I answer my own email.